Re: OpenBSD firewalls as virtual machine ?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Douglas A. Tutty
Date: Friday, September 21, 2007 - 9:36 pm

On Fri, Sep 21, 2007 at 11:12:10PM -0400, user@domain.invalid.holland-consulting.net wrote:

Hi Nick.

I understand your reasons.  To me they look like reasons for separate
firewalls on separate boxes.  In the scenarios you mention, would you
put separate firewalls on one machine?   

If I was going to put them all on one machine, I'd separate the
administration of the box itself (me) from the people responsible for
rule sub-sets.  E.g. if one sub-firewall is dealing with traffic between
NICs 1 & 2 (call it channel A), another between NICs 3 & 4 (call it
channel B), I'd have the channels A and B admins submit rules sub-sets
via rsync to the box.  My script would then sanity check (ensure that
they only dealt with the interfaces they were assigned) then incorporate
all of them into a master rule-set that would then get tested and then
put on-line.  I would think that this, being only one firewall, would be
simpler than several firewalls in VMs on one box;  possibly more secure
given the comments in this thread about the porus isolation between VMs.

That's just how I would think of it.  OTOH, I've never done any
virtualization and never been into a proper data center.

Doug.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OpenBSD firewalls as virtual machine ?, Josh, (Thu Sep 20, 6:09 pm)
Re: OpenBSD firewalls as virtual machine ?, Jason Dixon, (Thu Sep 20, 6:35 pm)
Re: OpenBSD firewalls as virtual machine ?, Nick Holland, (Thu Sep 20, 6:52 pm)
Re: OpenBSD firewalls as virtual machine ?, bofh, (Thu Sep 20, 6:53 pm)
Re: OpenBSD firewalls as virtual machine ?, Jason Dixon, (Thu Sep 20, 7:15 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Thu Sep 20, 11:18 pm)
Re: OpenBSD firewalls as virtual machine ?, Craig Skinner, (Fri Sep 21, 1:03 am)
Re: OpenBSD firewalls as virtual machine ?, Kent Watsen, (Fri Sep 21, 5:07 am)
Re: OpenBSD firewalls as virtual machine ?, Tony Sarendal, (Fri Sep 21, 5:58 am)
Re: OpenBSD firewalls as virtual machine ?, Scott Wells, (Fri Sep 21, 6:19 am)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Fri Sep 21, 7:48 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Fri Sep 21, 7:52 am)
Re: OpenBSD firewalls as virtual machine ?, Craig Skinner, (Fri Sep 21, 8:09 am)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 8:17 am)
Re: OpenBSD firewalls as virtual machine ?, bofh, (Fri Sep 21, 12:29 pm)
Re: OpenBSD firewalls as virtual machine ?, Stuart Henderson, (Fri Sep 21, 12:51 pm)
Re: OpenBSD firewalls as virtual machine ?, Ted Unangst, (Fri Sep 21, 1:28 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 2:15 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 2:16 pm)
Re: OpenBSD firewalls as virtual machine ?, Claudio Jeker, (Fri Sep 21, 3:34 pm)
Re: OpenBSD firewalls as virtual machine ?, Bryan Irvine, (Fri Sep 21, 4:09 pm)
Re: OpenBSD firewalls as virtual machine ?, Tony Sarendal, (Fri Sep 21, 4:10 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Fri Sep 21, 5:06 pm)
Re: OpenBSD firewalls as virtual machine ?, user, (Fri Sep 21, 8:12 pm)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Fri Sep 21, 9:36 pm)
Re: OpenBSD firewalls as virtual machine ?, Henning Brauer, (Sat Sep 22, 4:29 am)
Re: OpenBSD firewalls as virtual machine ?, Nick Holland, (Sat Sep 22, 7:53 am)
Re: OpenBSD firewalls as virtual machine ?, Douglas A. Tutty, (Sat Sep 22, 8:36 am)
Re: OpenBSD firewalls as virtual machine ?, ttw+bsd, (Sat Sep 22, 3:50 pm)
Re: OpenBSD firewalls as virtual machine ?, Luca Corti, (Sat Sep 22, 4:35 pm)
Re: OpenBSD firewalls as virtual machine ?, Darren Spruell, (Sat Sep 22, 4:45 pm)
Re: OpenBSD firewalls as virtual machine ?, n0g0013, (Sat Sep 22, 5:12 pm)
Re: OpenBSD firewalls as virtual machine ?, Eduardo Tongson, (Sat Sep 22, 8:12 pm)
Re: OpenBSD firewalls as virtual machine ?, David Gwynne, (Mon Sep 24, 4:59 am)
Re: OpenBSD firewalls as virtual machine ?, Die Gestalt, (Mon Sep 24, 5:56 am)